tripdout 1 day ago

This is almost exactly this website [0] which is also on the frontpage of HN. Wow.

0: https://news.ycombinator.com/item?id=49297469

  • yourbestcrab 21 hours ago

    I was searching for the logo like an *-hole, but I had to settle for their "men's public restroom" logo instead.

  • angoragoats 20 hours ago

    And this one, which is on the front page right now:

    https://news.ycombinator.com/item?id=49307700

    • angoragoats 15 hours ago

      Replying to my own post to note that the author of the app in my linked post is using an LLM to respond to everyone in the thread. They responded to me (with a clearly LLM written, sycophantic tone) and said that they updated the design. It looks less like the parody site now.

m132 1 day ago

It's not a Claude generated website without at least one `backdrop-filter: blur(1000px)` element that slows older machines to a crawl

addandsubtract 22 hours ago

It's missing the captcha that fails to load and then makes you retry three times.

possan 22 hours ago

Needs a cookie banner, 3s delayed sign up to our newsletter and enable push request

JK-Swizzle 1 day ago

It is missing the fade in on scroll.

noman-land 1 day ago

This needs bluish dark mode with accent color and pills with a little rounded colored border on just the left side.

Bolwin 1 day ago

Love the X logo that goes to bluesky

walrus01 1 day ago

> $ curl -fsSL install.sh | sh # you'd be stupid to run that, slop or not

I wish more people would point this out.

  • Akronymus 1 day ago

    I've legitimately seen one project that basically says to do that, but with "your ai agent". At least piping to sh is deterministic and, you can pipe to a filw and check the script

    https://github.com/0xeb/ghidrasql

    • walrus01 1 day ago

      "Claude, install these 215 npm dependencies from unvetted repositores, make no mistakes"

  • xigoi 1 day ago

    I still haven’t seen anyone point out how this is more dangerous than running an executable that you obtain any other way.

    • ffsm8 1 day ago

      you can detect `curl | bash` server-side and serve a different payload for those (compared to curl -O file, wget etc), hence its an effectively undetectable attack vector.

      Executables on the other hand can be inspected and prodded, so the likelihood of something going amiss and consequently security agencies finding out about it is significantly higher.

      neither of those is secure of course, we're just discussing different levels of dangers. And curl|bash being worse, albeit not that much

      (and the -L here is the extra cherry on top. piping a redirect to a shell is just monkas)

      • medstrom 18 hours ago

        > you can detect `curl | bash` server-side

        Oh wow, ok. So if anything, manually do `curl` and `sh` separately?

        • ffsm8 17 hours ago

          at that point, i'd put bash script up as being moderately more secure as its generally easier to audit them vs a binary.

          but i'Ve also gotta say that random binary download over web is also incredibly rare - usually its either a combination of both (the curl|bash ending in a random binary being downloaded) or the user actually installing via a packagemanager like apt, zypper, yum, dnf etc - and those packagemanagers generally do audit the main repositories, so theyre basically as secure as you can get in those contexts.

          but of course, everyone has their own thread model and i dont work in security (●'◡'●)

    • esafak 18 hours ago

      Because this way does not run security scanners.

willturman 1 day ago

The GitHub and X logos are chefs kiss

TacticalCoder 1 day ago

> Trusted by... six companies from the same YC cohort.

I giggled.

alertchecker 17 hours ago

It can't be AI-generated - AI doesn't swear

chunkyguy 1 day ago

What is wrong with this layout?

  • addandsubtract 22 hours ago

    There's nothing wrong with it, per se. It's just that it's overused and filled with random garbage stats that no one cares about.

cigarettestshir 1 day ago

This is one of my favorite things I've ever seen.

BoingBoomTschak 1 day ago

The fact that I can see it with JS disabled really breaks immersion here.

  • tosti 1 day ago

    I expected cloudflare turnstile and if that happens to work, flashing gray bars to "compensate" for an absurdly long loading time.

doublerabbit 1 day ago

If the layout is intentionally LLM generated, heh.